[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2003-1567Date: (C)2009-01-14   (M)2024-04-19


The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.8
Exploit Score: 8.6
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: NONE
  
Reference:
http://archives.neohapsis.com/archives/ntbugtraq/2003-q4/0321.html
OSVDB-5648
VU#288308
http://www.aqtronix.com/Advisories/AQ-2003-02.txt

CPE    1
cpe:/a:microsoft:internet_information_services:5.0
CWE    1
CWE-200
OVAL    1
oval:org.secpod.oval:def:2106734

© SecPod Technologies